Jason Edwards
Certified: The GIAC GCLD Audio Course
This course teaches you how to secure cloud environments the way real incidents unfold: misconfigurations, over-permissioned identities, weak network boundaries, and data exposure paths that are easy to miss until it’s too late. You’ll build a practical, defensible security posture across compute, containers, storage, and managed services by using hardened baselines, policy enforcement, continuous validation, and clear ownership. Along the way, you’ll learn how to reduce attack surface with immutable deployment patterns, least privilege workload identities, safe sharing defaults, and recovery-...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 63 — Detect identity abuse by correlating logins, token use, and privilege changes 10.02.2026 13:22
This episode focuses on identity abuse as a primary cloud attack pattern and shows how correlation across authentication, token activity, and privilege events produces stronger detections than any single log source. You’ll define identity abuse signals such as anomalous sign-in contexts, unexpected token usage, unusual role assumptions, and rapid privilege changes that do not match normal operatio...
Episode 62 — Network security monitoring in the cloud: choose signals that reveal attacker movement 10.02.2026 16:22
This episode teaches how to select network monitoring signals that actually expose attacker behavior, rather than collecting traffic data that cannot answer investigation questions. You’ll define what “movement” looks like in cloud terms, including unexpected east-west connections, unusual service-to-service calls, and traffic patterns that violate intended segmentation. We’ll tie these ideas to G...
Episode 61 — Protect administrative network services so management planes stay isolated and controlled 10.02.2026 14:55
This episode explains why administrative network services are a high-leverage target and how isolating management planes reduces the chance that a single workload compromise turns into full environment takeover. You’ll define what “management plane” means in practical terms, including administrative endpoints, control interfaces, and privileged network paths that should not be reachable from gener...
Episode 60 — Reduce exposure from load balancers, gateways, and proxies with strong defaults 10.02.2026 10:10
This episode explains how edge components like load balancers, gateways, and proxies often become the real perimeter in cloud, making their default configuration choices critical for security and exam-ready architecture reasoning. You’ll learn how these components route and terminate traffic, where encryption should be enforced, and how misconfiguration can expose admin interfaces, weak protocols,...
Episode 59 — Securing cloud networks: prevent misroutes, shadow paths, and accidental trust relationships 10.02.2026 10:39
This episode focuses on the subtle network failures that create major security problems, including misroutes that send traffic through unintended places, shadow paths that bypass intended controls, and trust relationships that expand without explicit approval. You’ll learn how these issues emerge from routing propagation, shared services, peering links, and overlapping network designs that are com...
Episode 58 — Validate network design continuously by testing intended paths versus actual reachability 10.02.2026 10:41
This episode teaches how to verify network security outcomes with evidence, not assumptions, by comparing what the design says should happen to what packets can actually do. You’ll define reachability validation as confirming allowed and denied paths across subnets, services, and accounts, then connect it to GCLD expectations around governance, monitoring, and continuous assurance. We’ll discuss w...
Episode 57 — Secure DNS and name resolution so attackers cannot redirect trust or hide access 10.02.2026 13:51
This episode focuses on DNS as a trust system and shows why it becomes both an attack tool and a defense dependency in cloud environments. You’ll learn how name resolution influences where traffic goes, how service discovery works, and why DNS misconfigurations can quietly bypass intended controls or enable redirection attacks. We’ll connect this to exam scenarios involving data exfiltration, man-...
Episode 56 — Encrypt network traffic properly across regions, services, and hybrid connections 10.02.2026 18:08
This episode explains how to ensure confidentiality and integrity for data in transit across complex cloud paths, a topic that appears on the GCLD exam as both a technical control and a governance requirement. You’ll define what “properly encrypted” means beyond a checkbox, including strong protocol use, validated certificate handling, and consistent enforcement across service-to-service traffic....
Episode 55 — Design private connectivity patterns that replace public exposure with controlled paths 10.02.2026 10:07
This episode teaches how private connectivity reduces attack surface by removing unnecessary internet exposure while still enabling required access between services, networks, and environments. You’ll learn how to reason about “private” in cloud terms, including which traffic stays on provider backbones, how access is authorized, and where enforcement and monitoring should occur. We’ll connect the...
Episode 54 — Control egress to reduce exfiltration paths and limit command-and-control reachability 10.02.2026 10:52
This episode explains why outbound traffic control matters in cloud environments and how it changes attacker economics by making exfiltration and command-and-control harder and noisier. You’ll define egress control as limiting where systems can send data, then connect it to exam scenarios involving data loss prevention, containment, and segmentation effectiveness. We’ll cover practical approaches...
Episode 53 — Control ingress with security groups, firewalls, and service-specific access policies 10.02.2026 14:33
This episode focuses on inbound access control as a primary defense layer and shows how the exam expects you to choose the right control for the right exposure point. You’ll compare security groups and firewalls as enforcement mechanisms, then expand into service-specific access policies where the service itself can restrict who may connect or call it. We’ll discuss best practices for least-access...
Episode 52 — Segment networks intentionally to reduce blast radius and limit lateral movement 10.02.2026 14:42
This episode explains segmentation as a deliberate risk-reduction strategy, not just a diagram exercise, and it connects directly to GCLD questions about architecture, governance, and incident containment. You’ll define segmentation in cloud terms using subnets, routing boundaries, and policy enforcement points, then learn how segmentation reduces attacker options after initial access. We’ll walk...
Episode 51 — Cloud networking technology: understand VPC or VNET primitives and routing behaviors 10.02.2026 15:31
This episode builds the cloud networking foundation the GCLD exam expects by clarifying what core primitives actually do in practice, including address spaces, subnets, route tables, and the separation between control-plane intent and data-plane behavior. You’ll learn how routing decisions are made, how default routes and propagated routes change traffic flow, and why “it should be isolated” is no...
Episode 50 — Normalize logs for correlation so patterns emerge across accounts and regions 10.02.2026 9:59
This episode explains how normalization improves detection and investigation by making diverse log sources comparable, searchable, and correlatable across a large cloud footprint. You’ll define normalization as transforming events into consistent fields, timestamps, identity representations, and action categories so analysts can pivot and link related activity without manual translation. We’ll con...
Episode 49 — Set retention intentionally so logs remain useful across incident and audit timelines 10.02.2026 9:20
This episode focuses on retention as a strategic decision that balances investigation needs, compliance expectations, and operational cost, which is a common governance tradeoff in GCLD-style exam questions. You’ll define retention in terms of time coverage needed to detect slow-moving attacks, support forensic reconstruction, and provide audit evidence across reporting periods. We’ll discuss how...
Episode 48 — Protect log integrity using centralized storage, immutability controls, and tight permissions 10.02.2026 9:58
This episode explains how logs become meaningful evidence only when their integrity is protected, which is directly relevant to exam questions on audit readiness and incident defensibility. You’ll learn why decentralized logs are fragile and how centralization reduces loss, improves correlation, and simplifies access control enforcement. We’ll cover immutability concepts, including write-once patt...
Episode 47 — Capture data access logs that reveal sensitive reads, writes, deletes, and sharing 10.02.2026 9:42
This episode focuses on data access logging as a way to detect and prove what happened to sensitive information, which is a recurring theme in cloud leadership and GCLD-style governance scenarios. You’ll learn what data access logs should include, such as object reads and writes, permission changes, share events, and bulk operations that indicate exfiltration or destructive activity. We’ll connect...
Episode 46 — Capture control-plane logs that show configuration changes and risky administrative actions 10.02.2026 10:59
This episode explains why control-plane logs are essential for governance, incident response, and exam questions that ask you to reason about configuration change history and administrative intent. You’ll define the control plane as the management layer where resources are created, modified, and destroyed, then identify the kinds of events that matter most: policy updates, network changes, identit...
Episode 45 — Capture identity logs that reveal misuse, privilege changes, and suspicious sign-ins 10.02.2026 11:24
This episode focuses on identity logs as a primary signal for cloud compromise, because many attacks begin and expand through account misuse rather than classic network intrusion. You’ll learn what identity logs should capture, including authentication events, MFA outcomes, token and session activity, role assumptions, and changes to group membership or privilege assignments. We’ll connect these s...
Episode 44 — Cloud Logging Fundamentals: choose log sources that answer real investigation questions 10.02.2026 11:45
This episode explains how to choose cloud log sources based on the questions you must answer during incidents, audits, and operational troubleshooting, which is a common scenario framing in the GCLD exam. You’ll define logging fundamentals by focusing on intent: determining who did what, where, when, and with what impact, across identity, control plane, workloads, and data access. We’ll cover prac...
Episode 43 — Extend built-in controls consistently across single-cloud and multi-cloud environments 10.02.2026 13:25
This episode teaches how to maintain consistent security outcomes when environments span one cloud provider or multiple providers with different native capabilities and terminology. You’ll connect exam-relevant governance principles—standardization, control mapping, and measurable evidence—to the practical work of translating identity, logging, encryption, and network controls across platforms. We...
Episode 42 — Operationalize secure landing zones that standardize identity, logging, and network controls 10.02.2026 15:08
This episode focuses on secure landing zones as the foundational environment where accounts, identity, logging, and network baselines are established before workloads arrive. You’ll define a landing zone as a standardized blueprint that enforces consistent guardrails, enabling the kind of predictable governance outcomes the GCLD exam expects you to reason about. We’ll explore how landing zones sim...
Episode 41 — Design security-by-default architectures using managed services and least-management surfaces 10.02.2026 16:54
This episode explains how to design cloud architectures that are secure by default, reducing reliance on constant manual hardening and minimizing the attack surface created by operating system and platform management tasks. You’ll connect the GCLD exam’s governance focus to practical design choices such as preferring managed services, limiting administrative entry points, and reducing the number o...
Episode 40 — Frameworks for built-in security: map provider native capabilities into reliable patterns 10.02.2026 10:48
This episode teaches how to translate provider-native security capabilities into repeatable patterns that teams can adopt consistently, which supports both exam reasoning and real governance outcomes. You’ll define built-in security as the native controls cloud providers offer—identity, logging, encryption, network controls, and monitoring—and learn how to organize them into a coherent design inst...
Episode 39 — Automate guardrails that block risky storage, network, and IAM configurations instantly 10.02.2026 12:06
This episode explains how automated guardrails prevent common cloud incidents by stopping dangerous configurations before they reach production, which is central to secure scaling and exam-driven governance decisions. You’ll define guardrails as enforceable controls that evaluate configurations in real time or near real time, then apply that concept to high-risk areas like public storage exposure,...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.